HIPAA
42 U.S.C. § 1320d et seq.; 45 C.F.R. Parts 160, 162, 164Health Insurance Portability and Accountability Act — Privacy, Security and Breach Notification Rules
In force since April 14, 2003
There is no omnibus federal consumer privacy law. Protection is sectoral — health, finance, credit, children, education, video and telephony each have their own statute, regulator and remedies — and the FTC's general authority over unfair or deceptive practices fills the gaps that remain.
The practical consequence: whether you owe a privacy duty federally depends on what kind of business you are, not on what data you hold. A fitness app holding heart-rate data owes nothing under HIPAA, because HIPAA covers health-care providers and plans rather than health data.
Health Insurance Portability and Accountability Act — Privacy, Security and Breach Notification Rules
In force since April 14, 2003
Gramm-Leach-Bliley Act — Privacy Rule and Safeguards Rule
In force since July 1, 2001
Fair Credit Reporting Act
In force since April 25, 1971
Children's Online Privacy Protection Act
In force since April 21, 2000
Family Educational Rights and Privacy Act
In force since November 19, 1974
Video Privacy Protection Act
In force since November 5, 1988
Telephone Consumer Protection Act
In force since December 20, 1991
Privacy Act of 1974
In force since September 27, 1975
Federal Trade Commission Act, Section 5 — unfair or deceptive acts or practices
In force since September 26, 1914
American Privacy Rights Act
A comprehensive federal consumer privacy framework with preemption of state law
Not enacted. Successive Congresses have advanced comprehensive privacy bills out of committee without floor passage; preemption of state law and a private right of action remain the two unresolved questions.
Status as of September 27, 2026
Congress.gov — search federal privacy legislationCongress.gov API — bill status as machine-readable data